$ cat writeup.md…
$ cat writeup.md…
ringzer0ctf
Task: Python2 encryptor implementing a hand-rolled Dual_EC_DRBG on NIST P-256 with two fixed points C/D; recover intercepted plaintext without the password. Solution: exploit the Dual_EC backdoor (D=d*C with tiny d=6002 found via BSGS) plus a decimal/binary length-mismatch that leaks the first keystream word verbatim in the ciphertext's leading digits, then advance the DRBG and XOR to decrypt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar